vulnerability

MFSA2026-11 Thunderbird: Security Vulnerabilities fixed in Thunderbird 147.0.2 and 140.7.2 (CVE-2026-2447)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Feb 16, 2026
Added
Feb 17, 2026
Modified
Apr 15, 2026

Description

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

Solutions

mozilla-thunderbird-upgrade-140_7_2mozilla-thunderbird-upgrade-147_0_2
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.